Vulnerability Name: | CVE-2002-0525 (CCN-8834) | ||||||||
Assigned: | 2002-04-11 | ||||||||
Published: | 2002-04-11 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: SCO Security Advisory CSSA-2002-038.0 Linux: inn format string and insecure open vulnerabilities Source: BUGTRAQ Type: UNKNOWN 20020411 Inn (Inter Net News) security problems Source: CCN Type: BugTraq Mailing List, Thu Apr 11 2002 - 13:22:01 CDT Inn (Inter Net News) security problems Source: MITRE Type: CNA CVE-2002-0525 Source: CCN Type: Internet Software Consortium (ISC) Web site INN: InterNetNews Source: XF Type: Vendor Advisory inn-rnews-inews-format-string(8834) Source: CCN Type: OSVDB ID: 6873 INN inews NTTP Response Format String Source: CCN Type: OSVDB ID: 6874 INN rnews NTTP Response Format String Source: BID Type: Exploit, Patch, Vendor Advisory 4501 Source: CCN Type: BID-4501 ISC INN Multiple Local Format String Vulnerabilties Source: CCN Type: BID-6049 ISC INN Multiple Insecure Open Call Vulnerabilities Source: XF Type: UNKNOWN inn-rnews-inews-format-string(8834) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |